Bug 1471752 - [abrt] will-crash: Will::Fail::a(): will_cpp_segfault killed by SIGSEGV
Summary: [abrt] will-crash: Will::Fail::a(): will_cpp_segfault killed by SIGSEGV
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Fedora
Classification: Fedora
Component: will-crash
Version: 25
Hardware: x86_64
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Richard Marko
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: abrt_hash:003b416e06e882be3597db7dd72...
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2017-07-17 11:56 UTC by Matej Marušák
Modified: 2017-07-17 12:01 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2017-07-17 12:01:25 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)
File: backtrace (3.01 KB, text/plain)
2017-07-17 11:56 UTC, Matej Marušák
no flags Details
File: cgroup (276 bytes, text/plain)
2017-07-17 11:56 UTC, Matej Marušák
no flags Details
File: core_backtrace (1.01 KB, text/plain)
2017-07-17 11:56 UTC, Matej Marušák
no flags Details
File: cpuinfo (1.26 KB, text/plain)
2017-07-17 11:56 UTC, Matej Marušák
no flags Details
File: dso_list (498 bytes, text/plain)
2017-07-17 11:56 UTC, Matej Marušák
no flags Details
File: environ (3.87 KB, text/plain)
2017-07-17 11:56 UTC, Matej Marušák
no flags Details
File: limits (1.29 KB, text/plain)
2017-07-17 11:56 UTC, Matej Marušák
no flags Details
File: machineid (135 bytes, text/plain)
2017-07-17 11:56 UTC, Matej Marušák
no flags Details
File: maps (2.81 KB, text/plain)
2017-07-17 11:56 UTC, Matej Marušák
no flags Details
File: mountinfo (5.72 KB, text/plain)
2017-07-17 11:56 UTC, Matej Marušák
no flags Details
File: namespaces (102 bytes, text/plain)
2017-07-17 11:56 UTC, Matej Marušák
no flags Details
File: open_fds (140 bytes, text/plain)
2017-07-17 11:56 UTC, Matej Marušák
no flags Details
File: proc_pid_status (1.29 KB, text/plain)
2017-07-17 11:56 UTC, Matej Marušák
no flags Details
File: var_log_messages (28 bytes, text/plain)
2017-07-17 11:56 UTC, Matej Marušák
no flags Details

Description Matej Marušák 2017-07-17 11:56:03 UTC
Version-Release number of selected component:
will-crash-0.10-2.fc24

Additional info:
reporter:       libreport-2.9.1.6.gdd487d.dirty
backtrace_rating: 4
cmdline:        will_cpp_segfault
crash_function: Will::Fail::a
executable:     /usr/bin/will_cpp_segfault
global_pid:     32237
kernel:         4.11.3-202.fc25.x86_64
runlevel:       N 5
type:           CCpp
uid:            1000

Truncated backtrace:
[New LWP 32237]
Core was generated by `will_cpp_segfault'.
Program terminated with signal SIGSEGV, Segmentation fault.
#0  Will::Fail::a (this=<optimized out>) at will_cpp_segfault.cc:14
14	            std::cout << s[666];

Thread 1 (LWP 32237):
#0  Will::Fail::a (this=<optimized out>) at will_cpp_segfault.cc:14
No locals.
#1  0x0000561323beda99 in Will::Fail::b (this=0x7ffe0c398ab0) at will_cpp_segfault.cc:25
No locals.
#2  0x0000561323bed8a3 in main (argc=<optimized out>, argv=<optimized out>) at will_cpp_segfault.cc:34
        f = {value = 1}
From                To                  Syms Read   Shared Object Library
0x00007f83daa25880  0x00007f83daad5059  Yes         /lib64/libstdc++.so.6
0x00007f83da696720  0x00007f83da707b7a  Yes         /lib64/libm.so.6
0x00007f83da47caa0  0x00007f83da48c8b5  Yes         /lib64/libgcc_s.so.1
0x00007f83da0d39d0  0x00007f83da223983  Yes         /lib64/libc.so.6
0x00007f83dad22ad0  0x00007f83dad40970  Yes         /lib64/ld-linux-x86-64.so.2
$1 = 0x0
rax            0x561323dee020	94640206176288
rbx            0x7ffe0c398ab0	140729103518384
rcx            0x7f83da1abae0	140204276628192
rdx            0x7f83dad19980	140204288612736
rsi            0x0	0
rdi            0x56132587ec20	94640234032160
rbp            0x561323bedaa0	0x561323bedaa0 <__libc_csu_init>
rsp            0x7ffe0c398a80	0x7ffe0c398a80
r8             0x7f83da476700	140204279555840
r9             0x7f83da4755e0	140204279551456
r10            0x56132587ec20	94640234032160
r11            0x246	582
r12            0x561323bed8f0	94640204077296
r13            0x7ffe0c398ba0	140729103518624
r14            0x0	0
r15            0x0	0
rip            0x561323beda4c	0x561323beda4c <Will::Fail::a()+44>
eflags         0x10206	[ PF IF RF ]
cs             0x33	51
ss             0x2b	43
ds             0x0	0
es             0x0	0
fs             0x0	0
gs             0x0	0
Dump of assembler code for function Will::Fail::a():
   0x0000561323beda20 <+0>:	lea    0xfd(%rip),%rsi        # 0x561323bedb24
   0x0000561323beda27 <+7>:	lea    0x2005f2(%rip),%rdi        # 0x561323dee020 <_ZSt4cout>
   0x0000561323beda2e <+14>:	sub    $0x18,%rsp
   0x0000561323beda32 <+18>:	mov    $0xf,%edx
   0x0000561323beda37 <+23>:	mov    %fs:0x28,%rax
   0x0000561323beda40 <+32>:	mov    %rax,0x8(%rsp)
   0x0000561323beda45 <+37>:	xor    %eax,%eax
   0x0000561323beda47 <+39>:	callq  0x561323bed868
=> 0x0000561323beda4c <+44>:	movzbl 0x29a,%eax
   0x0000561323beda54 <+52>:	lea    0x7(%rsp),%rsi
   0x0000561323beda59 <+57>:	lea    0x2005c0(%rip),%rdi        # 0x561323dee020 <_ZSt4cout>
   0x0000561323beda60 <+64>:	mov    $0x1,%edx
   0x0000561323beda65 <+69>:	mov    %al,0x7(%rsp)
   0x0000561323beda69 <+73>:	callq  0x561323bed868
   0x0000561323beda6e <+78>:	mov    0x8(%rsp),%rax
   0x0000561323beda73 <+83>:	xor    %fs:0x28,%rax
   0x0000561323beda7c <+92>:	jne    0x561323beda83 <Will::Fail::a()+99>
   0x0000561323beda7e <+94>:	add    $0x18,%rsp
   0x0000561323beda82 <+98>:	retq   
   0x0000561323beda83 <+99>:	callq  0x561323bed870
End of assembler dump.
== EXPLOITABLE ==

Comment 1 Matej Marušák 2017-07-17 11:56:07 UTC
Created attachment 1299798 [details]
File: backtrace

Comment 2 Matej Marušák 2017-07-17 11:56:09 UTC
Created attachment 1299799 [details]
File: cgroup

Comment 3 Matej Marušák 2017-07-17 11:56:11 UTC
Created attachment 1299800 [details]
File: core_backtrace

Comment 4 Matej Marušák 2017-07-17 11:56:12 UTC
Created attachment 1299801 [details]
File: cpuinfo

Comment 5 Matej Marušák 2017-07-17 11:56:13 UTC
Created attachment 1299802 [details]
File: dso_list

Comment 6 Matej Marušák 2017-07-17 11:56:15 UTC
Created attachment 1299803 [details]
File: environ

Comment 7 Matej Marušák 2017-07-17 11:56:17 UTC
Created attachment 1299804 [details]
File: limits

Comment 8 Matej Marušák 2017-07-17 11:56:18 UTC
Created attachment 1299805 [details]
File: machineid

Comment 9 Matej Marušák 2017-07-17 11:56:20 UTC
Created attachment 1299806 [details]
File: maps

Comment 10 Matej Marušák 2017-07-17 11:56:22 UTC
Created attachment 1299807 [details]
File: mountinfo

Comment 11 Matej Marušák 2017-07-17 11:56:23 UTC
Created attachment 1299808 [details]
File: namespaces

Comment 12 Matej Marušák 2017-07-17 11:56:25 UTC
Created attachment 1299809 [details]
File: open_fds

Comment 13 Matej Marušák 2017-07-17 11:56:26 UTC
Created attachment 1299810 [details]
File: proc_pid_status

Comment 14 Matej Marušák 2017-07-17 11:56:28 UTC
Created attachment 1299811 [details]
File: var_log_messages


Note You need to log in before you can comment on or make changes to this bug.